AAxaraOSPrivacy notice · v0.73 readiness

Privacy Notice

This notice describes AxaraOS's current product-level privacy controls and data handling categories. It supports POPIA/GDPR readiness but is not a statement that every deployment is automatically compliant; customers remain responsible for their own legal assessment, configuration and connected-provider obligations.

Account and workspace information

AxaraOS can process account identity, organisation details, workspace membership, brand configuration, subscription and billing evidence, usage records, audit evidence and the marketing data that users or connected providers supply to authorised product features. Password handling is delegated to the configured Supabase authentication service; AxaraOS does not store plaintext passwords.

Purposes and lawful basis

Data is used to provide and secure the service, operate requested marketing workflows, measure usage, maintain billing and audit evidence, support customer requests and prevent abuse. The Privacy Centre lets organisation administrators document processing purposes and their assessed lawful basis. AxaraOS does not infer that a lawful basis exists merely because data is publicly available or technically accessible.

AI and connected services

Configured AI, analytics, advertising, social, billing, email and search providers may receive the minimum information needed for the requested integration or workflow. Provider configuration does not by itself establish a processor/controller relationship or international-transfer safeguard; v0.73 therefore exposes those services for explicit review.

Marketing consent and outreach

Optional AxaraOS product marketing consent is separate from account operation and can be withdrawn in the Privacy Centre. Scout prospect outreach remains governed separately by public-source provenance, human compliance review, high-risk approval and durable suppression controls.

Your privacy controls

Authenticated users can submit access, portability, rectification, erasure, restriction, objection and consent-withdrawal requests and download a self-service account privacy snapshot. Formal requests may require identity verification, scoping and legal review before completion.

Retention and deletion

Organisation administrators can maintain retention policies and run dry-run reviews of aged records. v0.73 intentionally performs no automatic destructive deletion of production or audit data. Legal holds and applicable statutory, contractual or security obligations must be reviewed before deletion.

Security and abuse prevention

AxaraOS uses tenant isolation, audit records, configurable security controls and privacy-minimised keyed hashes in selected abuse-protection workflows. Sensitive credentials are kept server-side and are not exposed through client-facing configuration.

Contact and governance

Organisation administrators can set a privacy contact and primary jurisdiction in the Privacy Centre. Applicable legal deadlines, exceptions and regulator requirements remain authoritative over AxaraOS's configurable operational targets.

Create accountTerms of Service